CVE-2015-5723

high
Published 2016-06-07 · Modified 2024-11-30
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.2
VIR risk
7.8

Description

Doctrine Security Misconfiguration Vulnerability

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5723

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.4.8-1
debian debianbullseyefixed2.4.8-1
debian debianforkyfixed2.4.8-1
debian debiansidfixed2.4.8-1
debian debiantrixiefixed2.4.8-1
debian debian7.0affected
debian debian8.0affected

Package impact

EcosystemPackageVulnerableFixed
php Packagistdoctrine/annotations<1.2.71.2.7
php Packagistdoctrine/cache>=1.4.0,<1.4.21.4.2
php Packagistdoctrine/common<2.4.32.4.3
php Packagistdoctrine/common>=2.5.0-stable,<2.5.12.5.1
php Packagistdoctrine/orm>=2.5.0,<2.5.12.5.1
php Packagistdoctrine/mongodb-odm<1.0.21.0.2
php Packagistdoctrine/mongodb-odm-bundle<3.0.13.0.1
php Packagistzendframework/zendframework1>=1.12.0,<1.12.161.12.16
php Packagistzendframework/zend-cache>=2.5.0,<2.5.32.5.3
php Packagistaws/aws-sdk-php>=3.0.0,<3.2.13.2.1
php Packagistdoctrine/cache>=1.0.0,<1.3.21.3.2
php Packagistzendframework/zend-cache>=2.4.0,<2.4.82.4.8
php Packagistzendframework/zendframework>=2.4.0,<2.4.82.4.8
php Packagistzfcampus/zf-apigility-doctrine>=1.0.0,<1.0.31.0.3

Application impact

VendorProductVersionsFixed
zendzend-cache{"endIncluding":"2.4.7"}
zendzend-cache2.5.0
zendzend-cache2.5.1
zendzend-cache2.5.2
doctrine-projectobject_relational_mapper{"endIncluding":"2.4.7"}
doctrine-projectobject_relational_mapper2.5.0
doctrine-projectdoctrinemongodbbundle3.0.0
zendzend_framework{"endIncluding":"2.4.7"}
doctrine-projectcommon{"endIncluding":"2.4.2"}
doctrine-projectcommon2.5.0
doctrine-projectannotations{"endIncluding":"1.2.6"}
doctrine-projectmongodb-odm{"endIncluding":"1.0.1"}
doctrine-projectcache{"endIncluding":"1.3.1"}
doctrine-projectcache1.4.0
doctrine-projectcache1.4.1
zendzf-apigility-doctrine{"endIncluding":"1.0.2"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.